CVE-2024-5217: ServiceNow Incomplete List of Disallowed Inputs Vulnerability

Published Jul 10, 2024
·
Updated

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

Other sources

ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.

CISA

Affected Software

100 affected components
ServiceNow ServiceNow=utah
ServiceNow ServiceNow=utah-early_availability
ServiceNow ServiceNow=utah-patch_1
ServiceNow ServiceNow=utah-patch_1_hotfix_1
ServiceNow ServiceNow=utah-patch_1_hotfix_1a
ServiceNow ServiceNow=utah-patch_1_hotfix_1b
ServiceNow ServiceNow=utah-patch_1_hotfix_2
ServiceNow ServiceNow=utah-patch_10
ServiceNow ServiceNow=utah-patch_10_hotfix_1
ServiceNow ServiceNow=utah-patch_10_hotfix_2
ServiceNow ServiceNow=utah-patch_10a
ServiceNow ServiceNow=utah-patch_10a_hotfix_1
ServiceNow ServiceNow=utah-patch_10b
ServiceNow ServiceNow=utah-patch_2
ServiceNow ServiceNow=utah-patch_2_hotfix_1
ServiceNow ServiceNow=utah-patch_2_hotfix_2
ServiceNow ServiceNow=utah-patch_2_hotfix_3
ServiceNow ServiceNow=utah-patch_2_hotfix_4
ServiceNow ServiceNow=utah-patch_3
ServiceNow ServiceNow=utah-patch_3_hotfix_1
ServiceNow ServiceNow=utah-patch_3_hotfix_1b
ServiceNow ServiceNow=utah-patch_4
ServiceNow ServiceNow=utah-patch_4_hotfix_1
ServiceNow ServiceNow=utah-patch_4_hotfix_2
ServiceNow ServiceNow=utah-patch_4_hotfix_2a
ServiceNow ServiceNow=utah-patch_4_hotfix_2b
ServiceNow ServiceNow=utah-patch_4_hotfix_3
ServiceNow ServiceNow=utah-patch_4_hotfix_3b
ServiceNow ServiceNow=utah-patch_4_hotfix_4
ServiceNow ServiceNow=utah-patch_4_hotfix_4b
ServiceNow ServiceNow=utah-patch_4_hotfix_5
ServiceNow ServiceNow=utah-patch_5
ServiceNow ServiceNow=utah-patch_5_hotfix_1
ServiceNow ServiceNow=utah-patch_6
ServiceNow ServiceNow=utah-patch_6_hotfix_1
ServiceNow ServiceNow=utah-patch_6_hotfix_2
ServiceNow ServiceNow=utah-patch_7
ServiceNow ServiceNow=utah-patch_7_hotfix_1
ServiceNow ServiceNow=utah-patch_7_hotfix_2
ServiceNow ServiceNow=utah-patch_7a
ServiceNow ServiceNow=utah-patch_7b
ServiceNow ServiceNow=utah-patch_8
ServiceNow ServiceNow=utah-patch_8_hotfix_2
ServiceNow ServiceNow=utah-patch_9
ServiceNow ServiceNow=utah-patch_9_hotfix_1
ServiceNow ServiceNow=utah-patch_9_hotfix_1a
ServiceNow ServiceNow=utah-patch_9_hotfix_1b
ServiceNow ServiceNow=vancouver
ServiceNow ServiceNow=vancouver-patch_1
ServiceNow ServiceNow=vancouver-patch_1_hotfix_1
ServiceNow ServiceNow=vancouver-patch_2
ServiceNow ServiceNow=vancouver-patch_2_hotfix_1
ServiceNow ServiceNow=vancouver-patch_2_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_2_hotfix_2
ServiceNow ServiceNow=vancouver-patch_2_hotfix_3
ServiceNow ServiceNow=vancouver-patch_2_hotfix1a
ServiceNow ServiceNow=vancouver-patch_3
ServiceNow ServiceNow=vancouver-patch_3_hotfix_1
ServiceNow ServiceNow=vancouver-patch_3_hotfix_2
ServiceNow ServiceNow=vancouver-patch_3_hotfix_3
ServiceNow ServiceNow=vancouver-patch_3_hotfix_4
ServiceNow ServiceNow=vancouver-patch_4
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1b
ServiceNow ServiceNow=vancouver-patch_4_hotfix_2b
ServiceNow ServiceNow=vancouver-patch_5
ServiceNow ServiceNow=vancouver-patch_5_hotfix_1
ServiceNow ServiceNow=vancouver-patch_6
ServiceNow ServiceNow=vancouver-patch_6_hotfix_1
ServiceNow ServiceNow=vancouver-patch_7
ServiceNow ServiceNow=vancouver-patch_7_hotfix_1
ServiceNow ServiceNow=vancouver-patch_7_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2a
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2b
ServiceNow ServiceNow=vancouver-patch_7_hotfix_3a
ServiceNow ServiceNow=vancouver-patch_7_hotfix_4
ServiceNow ServiceNow=vancouver-patch_7_hotifix_1a
ServiceNow ServiceNow=vancouver-patch_7_hotifix_1b
ServiceNow ServiceNow=vancouver-patch_7_hotifix_2a
ServiceNow ServiceNow=vancouver-patch_7_hotifix_2b
ServiceNow ServiceNow=vancouver-patch_8
ServiceNow ServiceNow=vancouver-patch_8_hotfix_1
ServiceNow ServiceNow=vancouver-patch_8_hotfix_2
ServiceNow ServiceNow=vancouver-patch_8_hotfix_3
ServiceNow ServiceNow=vancouver-patch_9
ServiceNow ServiceNow=washington_dc
ServiceNow ServiceNow=washington_dc-patch_1
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_2
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_2a
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_2b
ServiceNow ServiceNow=washington_dc-patch_2
ServiceNow ServiceNow=washington_dc-patch_2_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_3
ServiceNow ServiceNow=washington_dc-patch_3_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_4
ServiceNow ServiceNow=washington_dc-patch_5
ServiceNow Utah, Vancouver, and Washington DC Now Platform

Event History

Jul 10, 2024
CVE Published
via MITRE·04:28 PM
Data Sourced
via MITRE·04:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 25, 2024
News Published
via BleepingComputer·08:58 PM
News Published
via BleepingComputer·09:00 PM
Jul 29, 2024
Known Exploited
via CISA·12:00 AM
News Published
via Dark Reading·08:46 PM
Dec 20, 2024
News Published
via Dark Reading·12:00 AM
May 26, 2025
News Published
via The Register·04:28 AM
News Published
via The Register·04:32 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-5217?

CVE-2024-5217 is considered a critical vulnerability that allows unauthenticated remote code execution in the ServiceNow platform.

2

How do I fix CVE-2024-5217?

To remediate CVE-2024-5217, it is essential to apply the latest patches or updates provided by ServiceNow for the affected versions.

3

Which versions of ServiceNow are affected by CVE-2024-5217?

CVE-2024-5217 affects the Utah, Vancouver, and Washington DC releases of ServiceNow.

4

Can CVE-2024-5217 be exploited without authentication?

Yes, CVE-2024-5217 can be exploited by unauthenticated users, leading to potential remote code execution.

5

What kind of impact can CVE-2024-5217 have on my system?

The impact of CVE-2024-5217 can be severe, as it allows attackers to execute arbitrary code within the ServiceNow environment, risking data integrity and security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203